random pop up and i can not run any software

Discussion in 'Malware Help (A Specialist Will Reply)' started by clock1, Feb 18, 2007.

  1. clock1

    clock1 Private E-2

    My office PC is infected, IE keeps popping dozens of sites.
    This is the situation now:
    1- Norton stopped running, a message said that there is unauthorized virus or attack control the software and I must visit the support page, I tried to download the fixer, but it did not do anything.
    2- I tried to uninstall Norton from control panel, but it kept asking for several missing files.
    3- I used the removal tool from Norton website to remove the program.
    4- I tried to re-install Norton again using 2 different versions , but I can not install it , because it keep pop-ing a message asking for missing files " can't find NAVAPW32.exe" and other files .
    5- Norton is not installed on my PC now.
    6- So I tried to run spy bot but I had a message that the software is missing.
    7- Trying to un-install and re-install, but I can not run it after installing it missing files message.
    8- Spybot is not installing on my PC now
    9- I CANNOT LOG TO THE SAFE MODE !!
    10- I cannot run most of software. Each software gives a message that there is a missing file and it can not run.
    11- I am running a scan using ewido now ( in normal mode ) and I put to result after finishing.
    12- Nothing in my PC regarding to ewido report
    13- I made a stinger scan , and also the PC was clean.
    14- I followed your instructions :

    Step 0: done
    Step 1 : using CCleaner - done
    Step 2: Enable viewing of hidden files, system files and file extensions -done
    Step 3: done
    Step 4 : Downloading Tools – done

    - Problems in step 4 :

    1-As I mentioned I cannot run spy bot.
    2-Counter spy : freeze in the middle of scanning , but it detect bagle.SP worm generic , and I couldn't remove it because the software freeze in the middle of process , I tried running it twice but I failed.
    3-AVG anti spy ware : "failed to save package" this is the message I receive after the updating.
    I ran it anyway , and it didn't find anything, I attached the log.



    Step 5 :
    - I can access to the safe mode , I receive a message means that there is some changes made by a software or hardware cause that I cannot access to the safe mode, I ran the scan in normal mode.
    -Bitdefender :"failed to update virus definition" this is the message I receive , I ran the scan

    - Panda ActiveScan :done
    - GetRunKey:I had a message:"c:\windows\system32\cmd.exe,c:\prog~\symentac\s32vnt.dll.. an installable virtual device driver dialed DLL , initialization.choose close to terminate" I chossed closed and I found about 22 files on c:\ , I zipped them in the attachement.
    - ShowNew:I received the same message as above , I choosed ignore and I had the newfiles.txt


    Step6:hijackthis : I followed the instructions – done

    I noticed that inside task manager there is a file named hldrr.exe causes the pop up , when I close it IE stop popping up .


    Please HELP.
     

    Attached Files:

  2. clock1

    clock1 Private E-2

    Tje rest of attachment

    I couldn't upload the zip files containing the 22 files of getrunkey.

    tell me what to do.

    thankx
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There is only ONE file from GetRunKey that needs to be uploaded and that is runkeys.txt You are not getting GetRunKey to complete (and the other files should all dissappear when GetRunKey completes) This is due to the error you mentioned in your first message. This error message is clearly describe on the download page for GetRunKey and you need to apply that fix. Then attach the runkeys.txt log from GetRunKey.
     
  4. clock1

    clock1 Private E-2

    Ok, thank you and sorry for missing this step , i was very tired to notice it.

    Any way i found 2 files on c:\ .. xrnotif.txt and runkeys.

    i will upload both.

    I noticed that inside task manager there is a file named hldrr.exe causes the pop up , when I close it IE stop popping up . does it mean any thing ?

    Thank you
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not follow the directions in step 0 of the READ ME where it mentions MSconfig. This was also mentioned a second time in the HijackThis instructions. You must set things to Normal Startup mode. After doing this, confinue on with the below steps.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_08
    Safety Bar <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Continue by downloading a tool we will need - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it later.

    Please run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\system32\hldrrr.exe
    C:\WINDOWS\system32\hldrrr.exe

    After killing all the above processes, click Back.
    Then please click Scan and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: (no name) - {259F616C-A300-44F5-B04A-ED001A26C85C} - (no file)
    O4 - HKLM\..\Run: [hldrrr] C:\WINDOWS\system32\hldrrr.exe
    O4 - HKCU\..\Run: [hldrrr] C:\WINDOWS\system32\hldrrr.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O16 - DPF: {6CB5E471-C305-11D3-99A8-000086395495} - http://toolbar.google.com/data/ar/big/1.1.62-big/GoogleNav.cab
    O20 - Winlogon Notify: winzzd32 - winzzd32.dll (file missing)

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\hldrrr.exe
    C:\Program Files\Common Files\{D033E687-095F-3073-0317-030308120001}\Update.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).

    If Killbox does not reboot just reboot your PC yourself.

    After reboot locate the below folder and delete if found:
    C:\Program Files\Common Files\{D033E687-095F-3073-0317-030308120001}

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT


    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Feb 20, 2007
  6. clock1

    clock1 Private E-2

    Thank you chaslang
    This is the 2 log files , i will start now the procedures you mentioned.
    i found again this file "xrnotif" do i have to upload it once more ?
    If i will find something that i cannot do i will post first.
    Just to be sure , uninstalling :
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_08
    Safety Bar <-- should have been uninstalled in step 0 of the READ ME

    is from add and remove programs , right ?

    about the safety bar , i do not remember that i use it, but i will uninstall it any way .
     

    Attached Files:

  7. clock1

    clock1 Private E-2

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.2_08
    Safety Bar <-- should have been uninstalled in step 0 of the READ ME
    ------------------
    DONE

    Make sure you reboot after uninstalling the above!
    -----------------
    DONE

    Install the current version of Sun Java from: Sun Java Runtime Environment.
    ----------------
    DONE

    downloading Pocket KillBox
    -----------------
    DONE

    >>>>>>>>>>>>>>>>>>

    run HijackThis and click on the Open the Misc Tools Section button on the open page. Then select Open process manager on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click Kill process. Then click yes.

    C:\WINDOWS\system32\hldrrr.exe
    C:\WINDOWS\system32\hldrrr.exe

    I cannot find these 2 files.

    I attached a copy of all files inside process manager.

    These 2 lines appears in the process manager :
    3260 C:\DOCUME~1\Admin\LOCALS~1\Temp\~3.exe
    1612 C:\DOCUME~1\Admin\LOCALS~1\Temp\~6.exe
    when IE pop up, and it is not i don't find them in task manager, and some times I find files starting with ~f or ~c too.

    What shall I do now ?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes uninstalling means via Add/Remove programs!

    Please follow directions properly. I did not ask for a new HJT and GetRunKey log before running the procedure in message # 5. I did however ask for new logs from GetRunKey, ShowNew and HJT after running the procedure and I still need you to complete that procedure and attach the requested logs.

    Do not rely on Windows Task Manager for anything! It does not show all running processes and it does not tell you the location that the process is running from. The process manager in HijackThis is much better. There are also better process managers than what is in HijackThis.
     
  9. clock1

    clock1 Private E-2

    The log files.

    I still can't access to safe mode.
    can i install norton and spy bot now ?
     

    Attached Files:

    Last edited: Feb 21, 2007
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First just try Spybot!


    Did you install all of the below and do you know what they all are and do you use them?
    Now Copy the bold text below to notepad. Save it as fixSL.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Can you boot in safe mode now? If not, you will have to work that in the Software Forum because it does not appear to be malware causing the problem.
     
  11. clock1

    clock1 Private E-2

    After several installing and un-installing , Spybot started to work normally once again.
    I scanned using Spybot and my PC was clear.

    Can i try insalling Norton now ?

    I made an online scan using Panda , and the report said that my PC is infected confused - the log is in the attachement.

    Yes... what is wrong with this softwares ?
    1: shutdown
    2:antinetcut2
    3:Snarfer
    4:Virtual Magnifying Glass
    5:O4 - HKLM\..\Run: [lvsclnt] C:\WINDOWS\system32\lvsclnt.exe
    O4 - HKLM\..\Run: [Atwtusb] RUNDLL32 FuncKey.DLL,ExtFuncCall AA
    I really don't know what are these for confused .
    Done
    I can't boot in safe mode . i thought that it is caused by the Malware, so if we can fix and clean the PC , why can't we fix the safe mode problem ?
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not until we finish with your malware cleaning. Installing Norton with malware present could cause problems for Norton.

    I'll get to those in my next message. This is part of what we have been working on fixing.

    I don't understand your reply. First you said yes you installed them and then you said you don't know what they are for?????


    If it is not a malware related problem (still to be determined since we are not finished removing malware yet) then it has to be fixed in the Software Forum since we focus on malware removal in this forum.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox by doubleclicking on killbox.exe
    • select File, Cleanup, Delete All Backups
    • Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    • Then after it deletes the files click the Exit (Save Settings) button.
    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue.

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\system32\wintems.exe
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt.
    If you receive a PendingFileRenameOperations prompt, just click OK to continue (But please let me know if you receive this message!).
    If Killbox does not reboot just reboot your PC yourself.

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!


    After attaching the above logs, do the below.

    Run Pocket Killbox and select File, Cleanup, Delete All Backups

    Now please download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.
     
  14. clock1

    clock1 Private E-2

    I am sorry , i mean the last two softwares :
    O4 - HKLM\..\Run: [lvsclnt] C:\WINDOWS\system32\lvsclnt.exe
    O4 - HKLM\..\Run: [Atwtusb] RUNDLL32 FuncKey.DLL,ExtFuncCall AA

    What are they for ?

    Here is the 3 logs , and i didn't receive any PendingFileRenameOperations prompt.

    I will post the BlackLight log now .

    Can i delete the old log and reg files ?

    Thank you.
     

    Attached Files:

  15. clock1

    clock1 Private E-2

    The BlackLight log :

    Thank you
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your newfiles.txt log, it appears that Pocket Killbox did not find the below file to delete:

    C:\WINDOWS\system32\wintems.exe

    Does Panda still detect it?

    Don't worry about the log files, we will clean them up during my final steps.

    Do you run any software to like this: a Remote Control Tool for any network application that allows users to manage and control PCs or networks from a remote location.

    Does the below folder exist:

    C:\Program Files\LANVisor\
     
  17. clock1

    clock1 Private E-2

    Do you want me to do another online panda scan ?
    I searched inside C:\WINDOWS\system32 folder , and i didn't find any file named wintems.exe , do you want me to repeat the steps you mentioned in the previous post ?
    No , i only have Netcut
    No , and i made a search on my PC using the keyword *visior* , but i didn't find any exe or folder having this name .

    Thank you
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! That would be the only way to know if it is still detecting it.

    No.

    Doesn't it allow remote administration/control? Could that lvsclnt.exe process be for NetCut? See the below link for more info that comes up about this file:

    http://research.sunbelt-software.com/threatdisplay.aspx?name=LANVisor&threatid=48408

    The folder name ends in visor not visior. Using search will not find anything that is hidden or mark as a system file/folder. You have to configure search to do that. You should be looking manually using Windows Explorer which is what step 2 of the READ ME was configuring to see hidden files. Step 2 has nothing to do with Windows Search.
     
  19. clock1

    clock1 Private E-2

    1- The latest Panda scan is attached.

    2- About Netcut , this software is used just to cut adsl connection of any PC in our office network.

    3- Doesn't it allow remote administration/control?
    No

    4-Could that lvsclnt.exe process be for NetCut?
    I don't think so

    5- About LANVisor , this PC was in another network , and maybe this software was installed in , but when we received this PC , this SW wasn't installed.
    Any way , do you think that it is better to delete this file ?

    6-About visor , i made my search using the right word, and i searched manually , and for C:\WINDOWS\system32\wintems.exe too. the default search is ticked on search hidden files , and step 2 of the READ ME is done since the first day.

    Ok , what is next step now ?

    Thank you very much chaslang , i do appreciated your effort helping people :)
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just have HJT fix that O4 line which is sufficient for now. If it winds up causing any problems for something you did not realize you needed, you can restore from HJT's backups.

    I repeat, step 2 of the READ ME had nothing to do with Search. It only has to do with what shows in Windows Explorer. Windows Search is not the same thing. Looking for something in Windows Explorer is manual navigation. See this: Searching for Hidden Files on WinXP I'm not saying you need to do this, I'm just pointing out that saying Search implies you did something different than using Windows Explorer to manually look for files yourself.

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  21. clock1

    clock1 Private E-2

    Thank you chaslang

    1- what about this file :
    O4 - HKLM\..\Run: [Atwtusb] RUNDLL32 FuncKey.DLL,ExtFuncCall AA

    2- in msconfig>startup the file "C:\WINDOWS\system32\hldrrr.exe" still there , i tried to delete it following these steps used before :

    I received PendingFileRenameOperations prompt :eek: .

    And the file stills appear in startup menu !!

    3- i installed Norton and it works fine and i made a full scan , the PC was clean .

    4- I still cannot boot in safe mode , i googled about this topic , but there was different solutions , i am not sure what to do , i will post in software forum as you mentioned .

    5- Can we say that my PC is clean now ?

    Thank you very much for your effort , you do a great job helping people :)
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It may have somethings to do with this:
    http://www.bleepingcomputer.com/startups/atwtusb.exe-410.html


    Fix any O4 lines with that hldrrr.exe file name in it like we did in message # 4. Make sure it does not come back. Whatever you do, do not use MSconfig to control startups.

    Attach a new HJT log!

    Note: I will be out of town until next Monday evening! So unless another malware helper is around to pick this up, you will have to wait until I return.
     
  23. clock1

    clock1 Private E-2

    Hi chaslang
    The file :O4 - HKLM\..\Run: [Atwtusb] RUNDLL32 FuncKey.DLL,ExtFuncCall AA is related to the Graphic Tablet
    So there is no need to delete it .

    I made another HJT log , i searched for any trace of hldrrr.exe , but i didn't find it , some times i see in the Windows Task Manager> Processes |under Image Name Files start by number , the last one was 000199.exe or ~6.exe then they disapear !! is it normal ? .

    I usually use MSconfig to choose only 2 softwares to launch with the start up , how can i do that without the MSconfig ?

    Take care of yourself ;)

    Thank you
     

    Attached Files:

  24. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    I'll be looking after Chaslang's threads while he is out of town.

    MsConfig is not a startup manager. MsConfig is a diagnostic tool.

    Items you do not loading at startup are configure to not start via the programs preferences or options; and if unable to configure from the programs preferences then remove the HJT entry for that program.
     
  25. clock1

    clock1 Private E-2

    Hi Shadow_Puter_Dude
    I do run>Type msconfig to go to the System configuration utility > Startup tab
    then i ticke only what i want it to be loaded during the start up .
    Is that wrong?

    I am very sorry , but this point is not clear for me confused

    Is there any thing in my last HJT log ?
     
  26. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    MSConfig is not a StartUp Manager. It is purely a diagnostic tool. Nothing should be disabled using MSConfig. If you do not want items to load at system start then configure the item to not load using the preferences of the particular program you don't want to load or you can have HijackThis fix the 04 entries you don't want loading.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds